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Abstract 

We provide tight upper and lower bounds on the noise resilience of interactive communication 
over noisy channels with feedback. In this setting, we show that the maximal fraction of noise 
that any robust protocol can resist is 1/3. Additionally, we provide a simple and efficient robust 
protocol that succeeds as long as the fraction of noise is at most 1/3 — e. Surprisingly, both 
bounds hold regardless of whether the parties send bits or symbols from an arbitrarily large 
alphabet. 

We also consider interactive communication over erasure channels. We provide a protocol 
that matches the optimal tolerable erasure rate of 1/2 — e of previous protocols (Franklin et ah, 
CRYPTO T3) but operates in a much simpler and more efficient way. Our protocol works with 
an alphabet of size 4, in contrast to prior protocols in which the alphabet size grows as e —>• 0. 
Building on the above algorithm with a fixed alphabet size, we are able to devise a protocol for 
binary erasure channels that tolerates erasure rates of up to 1/3 — e. 


*Work done while at Univ. of Chicago. 
^Work done while a student at UCLA. 



1 Introduction 


In the interactive communication setting, Alice and Bob are given inputs x and y respectively, and 
are required to compute and output some function f(x, y) of their joint inputs. To this end, they 
exchange messages over a channel that may be noisy: up to an e-fraction of the transmitted bits 
may get flipped during the communication. Due to the noise, there is a need for error correction and 
sophisticated coding schemes that will allow the parties to successfully conduct the computation, yet 
keep the communication complexity small, ideally at most linear in the communication complexity 
of computing the same function over a noiseless channel (hereinafter, we say that such a scheme 
has a constant rate). 

Coding schemes for interactive communication have been extensively explored, starting with 
the pioneering work of Schulman [Sch92, Sch93, Sch96] who gave the first constant rate scheme to 
resist up to a 1/240-fraction of bit flips. Almost two decades later, Braverman and Rao [BR11] 
showed a constant rate coding scheme that successfully computes any function, as long as the 
fraction of corrupted transmissions is at most 1/4 — e. Furthermore, they show that it is impossible 
to resist noise of 1/4 or more, for a large and natural class of robust protocols. In robust protocols 
both parties are guaranteed to agree whose turn it is to speak at each round, regardless of the 
noise, e.g., when their order of speaking is a fixed function of the round number (see definition in 
Section 2 below). It should be noted that the above result of 1/4 — e applies only when the parties 
send symbols from a large alphabet, whose size is growing as e goes to zero. When the parties 
are restricted to sending bits, the coding scheme of Braverman and Rao [BR11] tolerates up to a 
(1/8 — e)-fraction of bit flips. The question of determining the maximal tolerable noise for binary 
channels is still open. 

In this paper we examine different types of communication channels and noise. Specifically, 
we consider channels with feedback and erasure channels. In the former it is assumed that after 
each transmission, the sender learns the (possibly corrupted) symbol received by the other side, 
i.e., there is a noiseless feedback. In the erasure channel case, the noise can turn any symbol into 
an “erasure” (denoted _L), but it cannot alter the transmission into a different valid symbol. Both 
erasure channels and channels with feedback have been studied in the classical one-way setting 
[Sha48, Ber64] albeit typically more from a perspective of optimizing communication rates. 

For each of these channels we examine the maximal tolerable noise for interactive communica¬ 
tion, both when the parties are restricted to sending bits and in the general case where they are 
allowed to send symbols from a larger alphabet. 

1.1 Our Results 


channel type 

alphabet 

order of speaking 

lower bound 

upper bound 

feedback 

ternary &; large 

fixed 

1/4 

1/4 

feedback 

binary 

fixed 

1/6 

1/6 

feedback 

binary & large 

arbitrary 

1/3 

1/3 

erasure 

4-ary & large 

fixed 

1/2 

1/2 

erasure 

binary 

fixed 

1/3 

?? 


Table 1: A summary of the lower (achievability) and upper (impossibility) bounds for the maxi¬ 
mum tolerable error rate for all settings considered in this paper. 
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Interactive communication over channels with feedback. We completely solve the question 
of the maximal tolerable noise for robust interactive protocols over channels with feedback, both 
for the binary alphabet and the large alphabet case. We note that while in the standard noisy 
model the parties in a robust protocol must have a fixed order of speaking which depends only on 
the round of the protocol [BR11], this is not the case for noisy channels with feedback. Indeed, due 
to the feedback both parties know the symbols received at the other side and may determine the 
next party to speak according to their joint view. While this decision may depend on the noise, the 
parties maintain a consensus regarding the next party to speak. We can therefore refine the class 
of robust protocols into ones in which the order of speaking is fixed (i.e., a function of the round 
number) and ones in which the order is arbitrary (i.e., possibly dependent on the noise). We stress 
that these two subsets of protocols are still robust, and refer the reader to [GHS14, AGS13] for a 
discussion on adaptive (non-robust) protocols. 

As a helpful warm-up we first consider protocols with a fixed order of speaking. When the parties 
are allowed to send symbols from a large alphabet, we show for any e > 0 an efficient coding scheme 
with a constant rate that resists a noise rate of up to 1/4 — e. Although the same bounds were 
already given by [BR11, GH14] for standard noisy channels, our protocol is considerably simpler 
while also being computationally efficient. Moreover, while in other schemes the size of the alphabet 
increases as e —> 0, in our protocol a ternary alphabet suffices. The main idea is the following: the 
parties exchange messages as in the noiseless protocol, and use the feedback to verify that the 
messages were received intact. In case of a corrupted transmission, the parties transmit a special 
symbol ’ that instructs both parties to rewind the protocol to the step before the corrupted 
transmission. Building on the above coding scheme we provide for any e > 0 a simple and efficient 
binary protocol that resists up to a (1/6 — extraction of bit flips. 

Theorem 1.1. For any e > 0 and any function f(x,y) there exists an efficient robust coding 
scheme with a fixed order of speaking and a constant rate that correctly computes f(x,y) for each 
of the following settings: (i) over a channel with feedback with ternary alphabet, assuming at most 
a (1 /4 — e )-fraction of the symbols are corrupted, (ii) over a binary channel with feedback, assuming 
at most a (1/6 — e) -fraction of the bits are corrupted 

Additionally, we prove that the above bounds of 1/4 and 1/6 are tight for the general feedback 
channel, and the binary feedback channel, respectively. The impossibility result for the binary 
case has a particular interesting implication: since feedback channels are more powerful than stan¬ 
dard noisy channels, this impossibility applies also to robust protocols over standard binary noisy 
channels (i.e., without a feedback), narrowing the maximal tolerable noise for this setting to the 
region [1/8,1/6]. 

Theorem 1.2. There exists a function f(x,y), such that any robust binary interactive protocol, 
succeeds in computing f(x,y) with probability at most 1/2 assuming a \/&-fraction of bit-flips. 

Next, we consider robust protocols with arbitrary (noise-dependent) order of speaking. In this 
case the simple idea presented above immediately gives a higher noise-resilience of 1/3. The reason 
for this discrepancy in the bounds when we allow the order of speaking to be arbitrary stems from 
the following issue. When a transmission is corrupted, the sender is aware of this event and it 
sends a rewind symbol ’ on the next time it has the right to speaks. However, when the order 
of speaking is fixed (say, alternating), the parties “lose” one slot: while we would like the sender to 
repeat the transmission that was corrupted, the receiver is the next party to speak after the round 
where the '•<— ’ symbol is sent. If we allow the order of speaking to be arbitrary, we can avoid this 
excessive round and thus improve the noise resilience. 
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Translating the above idea to the binary case gives a protocol that resists a noise rate of 1/5 —e. 
However we can do better—we devise a protocol that resists noise rates up to 1/3 — e. Here the 
parties send messages of varying length, consisting of the original information followed by a varying 
amount of confirmation bits. The confirmation bits indicate whether or not the information was 
corrupted by the adversary. This practically forces the adversary to spend more of its corruption 
budget per message, or otherwise the receiving party learns about the corruption and simply ignores 
the message. 

Theorem 1.3. For any e > 0 and any function f(x, y ) there exists an efficient robust coding scheme 
with constant rate that correctly computes f(x,y ) over a binary channel with feedback assuming at 
most a (1/3 — e) -fraction of the bits are corrupted. 

It is interesting to mention that in contrast to all the previous settings and in contrast to the 
case of standard (uni-directional) error correction, the size of the alphabet (binary or large) makes 
no difference to the noise resilience of this setting. 

We also provide a matching impossibility bound of 1/3 that applies to any alphabet size, and 
in particular to the binary case. 

Theorem 1.4. There exists a function f(x, y), such that any robust interactive protocol over a chan¬ 
nel with feedback (with any alphabet) that computes f(x,y), succeeds with probability at most 1/2 if 
a 1 /3-fraction of the transmissions are corrupted. 

Interactive communication over erasure channels. In [FGOS13] it was shown that the 
maximal noise over erasure channels when a large alphabet can be used is 1/2 — e. This is trivially 
tight for protocols with a fixed order by completely erasing all the symbols sent by the party that 
speaks less. [In fact, this applies to any robust protocol—we show that robust protocols over erasure 
channels must have a fixed order of speaking!] When the parties are restricted to using a binary 
alphabet, it is possible to resist an erasure rate of 1/4 — e [FGOS13, BR11], The main drawback of 
these coding schemes is that they are not computationally efficient for the case of adversarial noise, 
and can take exponential time to complete in the worst case. 

Here we suggest a coding scheme with a constant rate that can tolerate an erasure rate of up 
to 1/2 — e, yet it is computationally efficient and very simple to implement. Moreover, our “large” 
alphabet is of size 6, regardless of e. 

Theorem 1.5. For any e > 0 and any function f(x,y) there exists an efficient, robust coding 
scheme with constant rate that correctly computes f(x,y) over an erasure channel with a 6-ary 
alphabet, assuming at most a (1/2 — e) -fraction of the bits are corrupted. 

The approach here is slightly different than the above schemes over channels with feedback. 
We no longer use a 4— symbol to rewind the simulation in a case of error, but instead each party 
always sends the next message according to the transcript accepted by that party so far. The key 
point is that erasures cannot make the receiver accept a wrong message. In other words, if the 
receiver receives a symbol (fi _L) it is guaranteed that this is indeed the symbol that was sent by 
the sender. It follows that the only issue possibly caused by an erasure is getting the players out 
of sync, i.e., getting them to simulate different rounds of the protocol. However, we show that this 
discrepancy in the simulated round is limited by ±1. Thus, sending a small parity of the party’s 
current simulated round (e.g., its round number modulus 3) is enough to re-gain synchronization 
and proceed with the simulation. 

Interestingly, the small and fixed alphabet size serves as a stepping stone in devising a protocol 
that works for binary erasure channels. Encoding each symbol of the 6-ary alphabet in the above 
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scheme into a binary string yields a protocol that resists erasures fractions of up to 3/10 — e. Yet, 
we are able to optimize the above simulation and reduce the size of the alphabet to only 4 symbols. 
This allows us to encode each symbol in the alphabet using a binary code with a very high relative 
distance, and obtain a protocol that tolerates a noise rate of 1/3 — e. This improves over the more 
natural and previously best known bound of 1/4 — e. 

Theorem 1.6. For any e > 0 and any function f(x,y ) there exists an efficient, robust coding 
scheme with constant rate that correctly computes f(x,y ) over a binary erasure channel, assuming 
at most a (1/3 — e )-fraction of the bits are corrupted. 

The only impossibility bound we are aware of is again the trivial bound of 1/2 [FGOS13, GH14] 
which applies even to larger alphabets. We leave determining the optimal erasure rate for coding 
schemes over binary erasure channels as an interesting open question. 

We summarize our results in Table 1. 

1.2 Other Related Work 

Maximal noise in interactive communication. As mentioned above, the question of inter¬ 
active communication over a noisy channel was initiated by Schulman [Sch92, Sch93, Sch96] who 
mainly focused on the case of random bit flips, but also showed that his scheme resists an adver¬ 
sarial noise rate of up to 1/240. Braverman and Rao [BR11] proved that 1/4 is a tight bound 
on the noise (for large alphabets), and Braverman and Efremenko [BE14] gave a refinement of 
this bound, looking at the noise rate separately at each direction of the channel (i.e., from Alice 
to Bob and from Bob to Alice). For each pair of noise rates, they determine whether or not a 
coding scheme with a constant rate exists. Another line of work improved the efficiency of coding 
schemes for the interactive setting, either for random noise [GMS11, GMS14], or for adversarial 
noise [BK12, BN13, GH14], 

Protocols in the above works are all robust. The discussion about non-robust or adaptive 
protocols was initiated by Ghaffari, Haeupler and Sudan [GHS14, GH14] and concurrently by 
Agrawal, Gelles and Sahai [AGS 13], giving various notions of adaptive protocols and analyzing 
their noise resilience. Both the adaptive notion of [GHS14, GH14] and of [AGS13] are capable of 
resisting a higher amount of noise than the maximal 1/4 allowed for robust protocols. Specifically, 
a tight bound of 2/7 was shown in [GHS14, GH14] for protocols of fixed length; when the length 
of the protocol may adaptively change as well, a coding scheme that achieves a noise rate of 1/3 is 
given in [AGS13], yet that scheme does not have a constant rate. 

Interactive communication over channels with feedback and erasure channels. To the 

best of our knowledge, no prior work considers the maximal noise of interactive communication over 
noisy channels with feedback. Yet, within this setting, the maximal rate of coding schemes, i.e., the 
minimal communication complexity as a function of the error rate, was considered by [Panl3, GH15] 
(the rate of coding schemes in the standard noisy channel setting was considered by [KR13, Hael4]). 

For erasure channels, a tight bound of 1/2 on the erasure rate of robust protocols was given 
in [FGOS13]. For the case of adaptive protocols, [AGS13] provided a coding scheme with a constant 
rate that resists a relative erasure rate of up to 1 — e in a setting that allows parties to remain 
silent in an adaptive way. The case where the parties share a memoryless erasure channel with a 
noiseless feedback was considered by Schulman [Sch96] who showed that for any function /, the 
communication complexity of solving / in that setting equals the distributional complexity of / 
(over noiseless channels), up to a factor of the channel’s capacity. 
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2 Preliminaries 


We begin by setting some notations and definitions we use throughout. We sometimes refer to a 
bitstring a £ {0,1}” as an array a[0],... ,a[n — 1]. a o b denotes the concatenation of the strings 
a and b. prefix fc (a) denotes the first k characters in a string a, and suffixfc(a) denotes the last 
k characters in a. For two strings a, b of the same length n, their Hamming distance d(a , b) is the 
number of indices 0 < i < n — 1 for which a[i\ ^ b[i\. 

Definition 2.1. A feedback channel is a channel CH : £ —» E in which at any instantiation noise 
can alter any input symbol a € E into any output a' £ E. The sender is assumed to learn the 
(possibly corrupt) output a’ via a noiseless feedback channel. 

An erasure channel is a channel CH : S — > SU{1} in which the channel’s noise is restricted 
into changing the input symbol into an erasure symbol _L. 

For both types of channels, the noise rate is defined as the fraction of corrupted transmissions 
out of all the channel instantiations. 

An interactive protocol ir over a channel CH, is a pair of algorithm n Alice-, 17 Bob that determine the 
next message to be communicated, given the input and the transcript so far. The communicated 
message is assumed to be a single symbol from the channel’s alphabet E. In all our protocols, 
|S| = 0(1). The protocol runs for |vr| rounds after which each party computes an output as 
a function of its input and the transcript that party sees. The Protocol is said to compute a 
function f(x,y ) if for any pair of inputs x, y, both parties output f(x,y). A coding scheme n is 
said to simulate n if for any pair of inputs x, y, the parties output n(x, y) —the transcript of running 
7 r on input (x, y) over a noiseless channel 

We further assume that at every given round only one party sends a message. Protocols in 
which the identity of the sender of each round is well defined and agreed upon both parties are 
called robust. 

Definition 2.2. We say that an interactive protocol n is robust ([BR11]) if, 

(1) for all inputs, the protocol runs for n rounds; (2) at any round, and given any possible noise, 
the parties are in agreement regarding the next party to speak. 

A fixed order protocol is one in which condition (2) above is replaced with the following 
(2’) there exist some function g : N —> {Alice, Bob} such that at any round i, the party that speaks 
is determined by g[i), specifically, it is independent of the noise. 

Note that any fixed-order protocol is robust, but it is possible that a robust protocol will not 
have a fixed order (see, e.g., Algorithm 2, or the coding scheme of Theorem 3.3 in the case of 
channels with noiseless feedback.). In that case we say that the robust protocol has an arbitrary or 
noise dependent order of speaking. 

In the following we show how to take any binary alternating (noiseless) protocol, and simulate 
it over a noisy channel. Note that for any function / there exists a binary alternating (noiseless) 
protocol 7r, such that the communication of 7r is linear in the communication complexity of /, that 
is, 

CC(tt) = 0(CC(/)). 

Hence, simulating the above 7r with communication 0(CC(7r)) has a constant rate, since its com¬ 
munication is linear in CC(/). 
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Feedback Channels with a Large Alphabet: Upper and Lower 
Bounds 

3.1 Protocols with a fixed order of speaking 

Let us consider simulation protocols in which the order of speaking is fixed and independent of the 
inputs the parties hold, and the noise injected by the adversarial channel. We show that 1/4 is a 
tight bound on the tolerable noise in this case. The bound is the same as in the case of standard 
noisy channels (without feedback) [BR11], We begin with the upper bound, by showing a protocol 
that correctly simulates n r assuming noise level of 1/4 — e. It is interesting to note that the alphabet 
used by the simulation protocol is independent of e (cf. [BR11, FGOS13, GH14, BE14]); specifically, 
we use a ternary alphabet. In addition the simulation is deterministic and (computationally) efficient, 
given black-box access to n. 

Theorem 3.1. For any alternating noiseless binary protocol it of length n, and for any e > 0, there 
exists an efficient, deterministic, robust simulation of n over a feedback channel using an alphabet 
of size 3 and a fixed order of speaking, that takes O e (n) rounds and succeeds assuming a maximal 
noise rate of 1/4 — e. 

Proof. We use a ternary alphabet X = {0,1, •<—}. The simulation works in alternating rounds 
where the parties run 7r, and verify via the feedback that any transmitted bit is correctly received 
at the other side. Specifically, if the received symbol is either a 0 or a 1 the party considers this 
transmission as the next message of 7r, and extends the simulated transcript T accordingly. If 
the received symbol is 4—, the party rewinds three rounds of ir, that is, the party deletes the last 
four undeleted symbols of T. 1 Each party, using the feedback, is capable of seeing whether the 
transcript T held by the other side contains any errors, and if so, it sends multiple 4— symbols until 
the corrupted suffix is removed. The above is repeated N = n/4e times (where n = |7r|), and at 
the end the parties output T. The protocol is formalized in Algorithm 1. 

Note that due to the alternating nature of the simulation, each corruption causes four rounds 
in which T doesn’t extend: (1) the corrupted slot; (2) the other party talks; (3) sending a 4— 
symbol; (4) the other party talks. After step (4) the simulated transcript T is exactly the same 
as it was before (1). Also note that consecutive errors (targeting the same party 2 ) simply increase 
the amount of symbols the sender should send, so that each additional corruption extends the 
recovery process by at most another four rounds. Also note that corrupting a bit into a 4— has a 
similar effect: after four rounds, T is back to what it was before the corruption: (1) the corrupted 
slot; (2-4) re-simulating 7r after three bits of T were deleted. 

Therefore, with 1/4 — e noise, we have at most 4 • (1/4 — e)N = N(1 — 4e) rounds that are 
used to recover from errors and do not advance T. Yet, during the rest 4 eN = n rounds T extends 
correctly and the simulation succeeds to output the entire transcript of it. □ 

Next we prove it is impossible to tolerate noise rates above 1/4. 

Theorem 3.2. Any protocol with a fixed order of speaking that computes the identity function 
f(x,y) = (x,y), succeeds with probability at most 1/2 over a feedback channel assuming 1/4 of the 
transmission are corrupted. 

Proof. The proof is similar to the case of interactive communication over of a standard noisy channel 
(without feedback) [BR11]. Assume that Alice speaks for R rounds and without loss of generality 

lr The four symbols removed from T are the received ’ symbol plus three simulated rounds of 7r. 

2 consecutive corruptions targeting the other party will be corrected without causing any further delay. 
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Algorithm 1 A fixed-order simulation for channels with feedback 

Input: a binary alternating protocol ir of length n, a noise parameter e > 0, an input value x. 

Assume a fixed alternating order of speaking: Alice is the sender on odd *’s, and Bob is the sender on 
even Vs. 

1 : Set N = \n/ 4e"|, initialize T <— 0; T F 0. 

> T is the simulated transcript as viewed by the party. We can split T into 
two substrings corresponding to alternating indices: T s are the sent characters, and T R the received 
characters. Let T F be the characters received by the other side (as learned via the feedback channel). 

2: for i = 1 to N do 
3: if T f = T s then 

> run one step of 7r, given the transcript so far is T 

4: T<-To tt{x | T) 

5: T f •<— T f o (symbol recorded at the other side) 

6: else 

7: if sender: 

8: send a ‘t—’ symbol 

9: T^ToV 

10: T f T f o (symbol recorded at the other side). 

11: if receiver: 

12: extend T according to incoming symbol. 

13: if suffixi(T fl ) =‘«—’ or suffixi(T F ) =‘<— ’ then 

14: T < prefiX| T |_ 4 (T) 

(also delete the corresponding transmissions in T F ) 

15: Output T 


assume R < N/2 (note that since the protocol has a fixed order of speaking, the party that speaks in 
less than half the rounds is independent of the input and noise, and is well defined at the beginning 
of the simulation). Define EXPO to be an instance in which Alice holds the input x = 0, and we 
corrupt the first R/2 rounds in which Alice talks so that they are the same as what Alice would 
have sent had she held the input x = 1. Define EX PI to be an instance in which Alice holds the 
input x = 1, and we corrupt the last R/2 rounds in which Alice talks so that they are the same as 
what Alice sends during the same rounds in EXPO. 

Note that from Bob’s point of view (including his feedback) EXPO and EXP1 are indistinguish¬ 
able, thus Bob cannot output the correct x with probability higher than 1/2. In each experiment 
we corrupt only half of Alice’s slots, thus the total noise is at most R/2 < N/ 4. □ 

3.2 Protocols with an arbitrary order 

It is rather clear that the protocol of Theorem 3.1 “wastes” one round (per corruption) only due 
to the fixed-order of speaking: when a corruption is noticed and a <— symbol is sent, the parties 
would have liked to rewind only two rounds of 7r, exactly back to beginning of the round that 
was corrupted. However, this will change the order of speaking, since that round belongs to the 
same party that sends the symbol. This suggests that if we lift the requirement of a fixed-order 
simulation, and allow the protocol to adapt the order of speaking, the simulation will resist up to a 
fraction 1/3 of noise. In the following we prove that 1/3 is a tight bound on the noise for this case. 
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We remark that although the protocol is adaptive in the sense that the order of speaking may 
change due to the noise, both parties are always in consensus regarding who is the next party to 
speak. Indeed, using the feedback channel, both parties learn the symbols received at both sides. 
Such a joint view can uniquely determine the next party to speak, thus, the protocol is robust 
(Definition 2.2). 

Theorem 3.3. For any alternating noiseless binary protocol n of length n, and for any £ > 0, there 
exists an efficient, deterministic, robust simulation of n over a feedback channel using an alphabet 
of size 3, that takes O e {n) rounds and succeeds assuming a maximal noise rate of 1/3 — e. 

Proof. We use a ternary alphabet X = {0,1, <—}. The simulation protocol is similar to Algorithm 1: 
each party maintains a simulated transcript T, and uses the feedback to verify that the other party 
holds a correct simulated transcript. As long as there is no noise in the simulated transcript, the 
parties continue to simulate the next step of 7r given that the transcript so far is T. Otherwise, 
the party that notices a corruption sends a <— symbol at the next round assigned to that party. 
When a 4— symbol is received, the party rewinds ir by two rounds, that is, the party deletes the 
last three symbols of T. 3 The next party to speak is determined by 7 r(x | T R ,T F ); note that 
(T F ,T R ) Alice = (T R ,T F ) Boh , thus the parties progress according to the same view and are in-synch 
at all times. The above is repeated N = n/ 3e times (where n = |7r|), and at the end the parties 
output T. 

It is easy to verify that each corruption causes at most three recovery rounds, after which T is 
restored to its state prior the corruption: (1) the corrupted slot; (2) the other party talks; (3) 
sending a symbol; After step (3) the simulated transcript T is exactly the same as it was before 
(1), and the party that spoke at (1) has the right to speak again. Again, note that consecutive 
errors simply increase the amount of 4— symbols the sender should send, so that each additional 
corruption extends the recovery process by at most another three rounds. Also note that corrupting 
a bit into a <— has a similar effect: after three rounds, T is back to what it was before the corruption: 
(1) the corrupted slot; (2-3) re-simulating the two bits of T that were deleted. 

When the noise level is bounded by 1/3 — e, we have at most 3 • (1/3 — e)N = N( 1 — 3e) rounds 
that are used to recover from errors and do not advance T; yet, during the rest 3eN = n rounds 
T extends correctly. Therefore, at the end of the simulation the parties output a transcript of 7r 
with a correct prefix of length at least n, thus they successfully simulate ir. □ 

Theorem 3.4. Any robust protocol that computes the identity function f(x,y) = (x,y) over a feed¬ 
back channel with an error rate of 1/3, succeeds with probability at most 1/2. 

Proof. The proof is based on ideas from [GHS14] for proving a lower bound on the noise tolerable 
by adaptive protocols over a standard noisy channel (without feedback). 

Consider a protocol of length N, and suppose that on inputs x = y = 0, Bob is the party that 
speaks less during the first 2N/3 rounds of the protocol. Recall that due to the feedback, we can 
assume the parties are always in consensus regarding the party to speak on the next round, so 
that at every round only a single party talks; thus Bob talks at most N/3 times during the first 
2N/3 rounds. Consider the following experiment EXP1 in which x = 0,y = 1 however we corrupt 
Bob’s messages during the first 2N/3 rounds so that they are the same as Bob’s messages given 
y = 0. From Alice’s point of view, the case where Bob holds y = 0 and the case where y = 1 but all 
his messages are corrupted to be as if he had y = 0, are equivalent. Therefore, with the consensus 
assumption, in both cases Bob’s talking slots are exactly the same, and this strategy corrupts at 
most N/3 messages. 

3 The three symbols removed from T are the received ’ symbol plus two rounds of it. 



Now consider the following experiment EXPO in which x = y = 0, however, during the last N/3 
rounds of the protocol we corrupt all Bob’s messages to be the same as what he sends in EX PI 
during the same rounds. Note that due to the adaptiveness of the order of speaking in the protocol, 
it may be that Bob talks in all these N/3 rounds, but corrupting all of them is still within the 
corruption budget. 

Finally, in both EXPO and EXP1 Alice’s view (messages sent, received and feedback) is the same, 
implying she cannot output the correct answer with probability higher than 1/2. □ 

4 Feedback Channels with a Binary Alphabet: Upper and Lower 
Bounds 

We now turn to examine the case of feedback channels with a binary alphabet. We begin (Sec¬ 
tion 4.1) with the case that the robust simulation has a fixed order of speaking, and show a tight 
bound of 1/6 on the noise. We then relax the fixed-order requirement (Section 4.2) and show that 
1/3 is a tight bound on the noise in this case. It is rather surprising that simulations with binary 
alphabet reach the same noise tolerance of 1/3 as simulations with large alphabet. 

4.1 Protocols with a fixed order of speaking 

Theorem 4.1. For any alternating noiseless binary protocol 7r of length n, and for any e > 0, 
there exists an efficient, deterministic, robust simulation of n over a feedback channel with a binary 
alphabet and a fixed order of speaking, that takes O e (n) rounds and succeeds assuming a maximal 
noise rate of 1/6 — e. 

Proof. In Algorithm 1 we used a special symbol <— to signal that a transmission was corrupted and 
instruct the simulation to rewind. When the alphabet is binary such a symbol can not be used 
directly, but we can code it into a binary string, e.g., “00”. To this end, we first need to make 
sure that the simulation does not communicate 00 unless a transmission got corrupted. However, 
recall that while no corruption is detected, Algorithm 1 simply communicates the transcript of 
the protocol n it simulates. We therefore we need to preprocess ir so that no party sends two 
consecutive zeros (cf. [GH15]). This can easily be done by padding each two consecutive rounds 
in 7T by two void rounds where each party sends a T’ (two rounds are needed to keep the padded 
protocol alternating). Denote with n' the preprocessed protocol, and note that \n'\ = 2|7t|. 

We now simulate n' in a manner similar to Algorithm 1. The parties communicate in alternating 
rounds where at each round they send the next bit defined by tt' according to the current simulated 
transcript T. In case that a corruption is detected via the feedback, the sender sends the string 00 
to indicate a rewind request. Due the alternating nature of the simulation, it takes three rounds 
to complete communicating the rewind request. Whenever a party receives a 00 rewind command, 
both parties delete the last 6 bits of T (recall that both parties know the received symbols: one 
directly and the other via the feedback). Observe that we must remove an even number of bits so 
that the alternating order of speaking is maintained. Thus, although the erroneous bit is only 5 
rounds prior to receiving the command, we rewind six rounds, see Figure 1. The simulation is 
performed for N = \t:'\/Q£ = 0(|7r|) rounds at the end of which both parties output T. 

The analysis is similar to the proof of Theorem 3.1, and we thus omit here the full details. The 
only difference is that each corruption takes at most six rounds to recover. This implies a maximal 
tolerable noise level of 1/6 — e. □ 
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Figure 1: Illustration of rewinding the protocol after the first bit sent by Alice is corrupted. 


Even more interesting is the fact that the above protocol is the best possible, in terms of the 
maximal tolerable noise. Indeed, we show that in this setting, it is impossible to tolerate noise 
levels of 1/6 or higher. 

Theorem 4.2. Any binary protocol with a fixed order of speaking that computes the identity function 
f(x,y) = (x,y) over a feedback channel, succeeds with probability at most 1/2 assuming an error 
rate of 1/6. 

Proof. Assume a binary robust protocol 7r that computes the identity function f(x,y) = ( x,y ) 
where x, y belong to some domain of size at least 3; assume |7r| = N, and without loss of generality 
let Alice be the party that speaks at most T < N/2 times in the protocol. We show an adversarial 
strategy that corrupts at most 1/3 of Alice’s messages and makes Bob’s view look the same for two 
different inputs of Alice. A similar approach appears in [Ber64, Ch. 4], 

Assume Alice holds one of three inputs, xo,xi,X 2 - For a given instance of the protocol, define 
xo[i], x\[i}, X 2 [i\ to be the i-th bit sent by Alice for the respective inputs. Note that the i-th 
transmission may depend on the transcript so far. If we fix a transcript up to the round where Alice 
sends her i -th bit, and look at her next transmission, xo [*], aq [i], X 2 [/], we observe that either the bit 
value is the same for all xq, xi, X 2 , or it is the same for two of these inputs, and different for the third 
one. For every i <T, let maj(i) = majority(xo[i],xi[?'],X2[4]), gi ven that previous transmissions are 
consistent with the adversarial strategy described below, and let w[l, ... , T] = maj(O) ■ • • maj(T). 

The adversarial strategy only corrupts Alice, so we should describe what is being sent at each 
one of the T rounds in which Alice has the right of speak. The attack consists of two parts: the 
first R transmissions of Alice, and the last T — R transmissions, for a number R we set shortly. For 
the first part, i.e., any transmission i < R, we corrupt the transmission so it equals maj(i) (i.e., if 
Alice sends maj(i) we leave the transmission intact and otherwise we flip the bit). The number R 
is set to be the minimal round such that for at least one of xo,xi,X 2 , the above strategy corrupts 
exactly R — 2 T /3 bits up to round R (included). It is easy to verify we can always find a round 
2T/3 < R < T that satisfies the above: for every Xj the quantity d(w[ 1,... , R], Xj [1,..., R\) starts 
at 0, never decreases, and increases at most by one in every round. Furthermore since in the first 
part at most T corruptions happen over all rounds and all three inputs, at least for one input 
Xj the quantity d(w[ 1,... , R], Xj [1,..., R]) will grows from 0 to at most T /3. On the other hand, 
the quantity R — 2T/3 increases exactly by one in every round and thus goes from —2T/3 to T/3. 
Therefore, there exists a round R in which R — 2T/3 catches up with d(w[ 1,... , R], Xj[l,... , R]) 
for some input Xj. 

Let Xo be the input for which the number of corruptions up to round R is R — 2 T /3; note that 
xq minimizes d(w[ 1 ,... , R\,Xj[l,..., R]), or otherwise one of the other inputs would have satisfied 
d(w[l,... ,R'],Xj[ 1,..., A?']) = R' — 2T/3 for some earlier round R' < R. We can therefore assume 
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without loss of generality that, 

d(w[ 1,... ,R],x 0 [ 1, • • • ,-R]) < d(w[ 1,... ,R],x i [1, - - ■ ,-R]) < d(w[ 1,... , J R],x 2 [l,..., -R]). (1) 

In the second part (the last T — R of Alice’s slots), we corrupt the f-th transmission so it equals xi[i]. 
That is, if Alice holds x\ we do nothing and if she holds xo we flip the bits as needed to correspond 
to what Alice would have sent on input x\. We do not care about x 2 in this second part. 

First note that from Bob’s point of view, the transcripts he sees given that Alice holds xo or x\ 
are exactly the same. Next, we claim that for both these inputs, the total amount of corruptions 
is at most T/3 < N/6. If Alice holds the input xq, then the total amount of corruptions is at most 

d(w[ 1,... , R],x 0 [l ,..., R\) + (T - R) < (R - 2T/3) + (T - R) = T/3 < N/6. 

If Alice holds x\ then we do not make any corruption during the last (T — R) rounds, and the 
total amount of corruptions is at most d(w[ 1,... , i?], x\\l ,..., R]). Since w is the majority, at each 
round i, there exists at most a single input Xj, for which d(w[i\,Xj[i\) = 1, while for both other 
inputs Xj/, the f-th transmitted bit is the same as their majority, d(w[i],Xji[i\) = 0. It follows that 

d(w[ 1,... ,R],x 0 [1, ...,R}) + d(w[ 1,... ,R],xi[l, ...,R]) + d(w[ 1,... ,-R],x 2 [l, • ■ • ,-R]) < R, 

thus with Eq. (1) and the fact that d(w[ 1,... , R\, xo[l,..., i?]) = R — 2T/3, we have 

R - 2T/3 + 2d(w[l, ...,R],xi[l,...,R])<R 

d(w[ 1,... , i?],xi[l,... ,R]) < T/3 < N/6. 


□ 

As a corollary of the above, we note that the same impossibility bound of 1/6 holds also 
for the case of standard noisy channel (i.e., without feedback). Clearly, adding the resource of 
noiseless-feedback can only improve the noise resilience. This simple observation immediately leads 
to Theorem 1.2. 

4.2 Protocols with an arbitrary order 

When the order of speaking needs not be fixed, we can improve the noise resilience of the simulation. 
A simple observation is that we can take the protocol of Theorem 4.1 and change it so after receiving 
a 00 rewind command, the parties rewind only 5 rounds of n instead of six. This immediately yields 
a protocol that resists noise levels up to 1/5. However, we can do even better. We devise a protocol 
in which the parties adaptively change the length of the messages they send and force the adversary 
to make more corruptions in order to cause the parties to accept a corrupted message. In case the 
adversary does not corrupt a substantial part of the message, the parties detect the corruption and 
discard the message. Similar ideas appear in [AGS13]. 

We show a binary protocol that tolerates noise levels of up to 1/3, similar to the simulations 
over feedback channels over large-alphabet. The bound of 1/3 is tight due to the impossibility of 
Theorem 3.4 that applies to binary channels as well. 

Theorem 4.3. For any alternating noiseless binary protocol n of length n, and for any e > 0, 
there exists an efficient, deterministic, robust simulation of ir over a feedback channel with a binary 
alphabet that takes O e {n) rounds and succeeds assuming a maximal noise rate of 1/3 — e. 
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The idea of the simulation is the following. The parties exchange messages of varying lengths. 
Each message consists of three parts: (a) 1 control bit (a rewind bit) — if set, this is an indication 
that the previous message was corrupted and the protocol should be rewound to the beginning of 
that message; (6) 1 bit of information — the next bit of 7r, in case no rewind is due; and (c) t > 1 
confirmation bits, set according to how parts (a) and (b) are received at the other side (according 
to the feedback): if the information and rewind bits are received intact, the confirmation bits will 
be ‘1’, or otherwise they will be ‘O’. The sender keeps sending confirmation bits, and checking via 
the feedback what the other side has received, until one of the following happens: 

1. the number of received O-conhrmation bits is at least 1/3 of the length of the current message 
— in this case the message is unconfirmed and the protocol rewinds to the beginning of that 
message (so that the sender has the right of speak again to send the same message). 

2. the number of received 1-confirmation bits minus the number of received O-confirmation bits 
is larger than 1/e — in this case the message is confirmed and the parties either rewind the 
protocol to the previous message of the sender (if the rewind bit is on), or the next simulated 
bit is the information bit. 

The parties perform the above until a total number of n/e 2 bits are communicated altogether. We 
formulate the simulation protocol in Algorithm 2. We now continue to prove Theorem 4.3. 

Proof. Consider a run of the protocol that did not compute the correct output, we will show that 
the noise must have been > 1/3 — 0(e). Let N be the amount of times the protocol executed 
the for-loop, and for i = 1,..., N let m; be the entire transmission communicated during the z-th 
instance of the loop (i.e., |rrq| = sentLength when reaching line 18). We know that |"h| = n/e 2 . 

Each message rn t can be confirmed or unconfirmed as explained above. If some message m; is 
confirmed it can either be correct or incorrect according to whether or not any of its first two bits, 
msg, was flipped. Divide the messages m i,... ,mjv into three disjoint sets: 

• U = {i < N | mi is unconfirmed} 

• C = {i < N | mi is confirmed and correct} 

• W = {i < N | m* is confirmed and incorrect} 

It is easy to see that an unconfirmed message has no effect on the simulated transcript as any 

such message is just ignored. If a message is confirmed, it can either be interpreted as an information 

bit or as a rewind request, and the simulation is similar to the algorithm of Theorem 3.3 where each 
one of the symbols {0,1,<—} is encoded into a longer message. Specifically, similar to Theorem 3.3, 
after a single incorrect message the simulation takes two correct messages in order to recover from 
the error, i.e., in order to revert to the state before the corruption. Also here, multiple erroneous 
messages just linearly accumulate, hence, 

Claim 4.4. The simulation of a protocol ir of length n succeeds as long as 

\C\-2\W\ > n. 

Next, we bound the length and noise rate of a message. To avoid edge cases caused by rounding, 
let us assume without loss of generality that 1/e is an integer (alternatively, replace e with e' for 
some 0 < e' < e with an integral reciprocal) 

Claim 4.5. For any i, \mfi is bounded by 2 + 3/e. 
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Algorithm 2 Simulation for channels with feedback with a binary alphabet 


Input: an alternating binary protocol 7r of length n, a noise parameter e > 0, an input value x. 
Initialize T 0. 

> T = (T s , T R , T f ) is the simulated transcript, separated to sent, received and feedback bits 

1: for i = do 

2: if rr(x | T f ,T r ) is your turn to speak then 

3: sentLength 2 

4: conf 0 4— 0, con 4— 0 

5: if T s = T f then 

6 : rewind = 0 

7: else 

8: rewind = 1 

9: msg 4— n(x \ T F , T R ) o rewind 

10: send msg 

11: while (con/ 0 < sentLength/ 3) and ( con — conf 0 < 1/e) do 

12: if msg received correctly then > verify via the feedback 

13: send 1 

14: else 

15: send 0 

16: sentLength 4— sentLength + 1 

17: conf b <r- conf b + 1 > b is the bit received at the other side (learned via the feedback) 


> No corruptions are known 
> The transcript at the other side is corrupt 


18: if con/ 0 > sentLength / then > message is not confirmed 

19: continue (next for loop instance) 

20: else if con/) — conf 0 > 1/e then > message is confirmed: rewind or advance T 

according to info/rewind received at other side 
21: if (rewind bit recorded at the other side) = 0 then 

22: T s T s on{x | T s ,T r ) 

23: T f <r- T f o (info bit recorded at the other side) 

24: else if (rewind bit recorded at the other side) = 1 then 

> Remove from T the last two simulated rounds 

25: T r <— prefix| T K|_ 1 (T ii ) 

26: T s prefiX| T s|. -i(T s ) 

27: T f 4— prefix| T F|_ 1 (T' F ) 

28: else o The other party is the speaker at this round 

29: Record msg , and confirmation bits according to the conditions of the while loop on line 11. 

30: If msg unconfirmed (line 18), ignore msg and continue. 

31: If msg confirmed (line 20): 

either extend T R (if rewind = 0) or delete the suffix bit of T R 1 T s , T F (if rewind =1). 

32: If more than n/e 2 bits were communicated, terminate and output T 











Proof. Assume a message reaches length 2 + 3/e, and consider its 3/e confirmation bits: If 1 + 
1/e of these bits are zeros, then the message is unconfirmed since (1 + l/e)/(2 + 3/e) > 1/3. 
Otherwise, there are at most 1/e zeros and at least 3/e — 1/e > 2/e ones, thus the difference 
between confirmation zeros and ones is at least 1/e and the message is confirmed. □ 


Note that for a confirmed message, 2 + 1/e < \rrii\ < 2 + 3/e, and for an unconfirmed message 
3 < I'm*| < 2 + 3/e. Since the total amount of bits the protocol communicates is n/e 2 , we have 

\C\ + \W\<- £ . ( 2 ) 

The specific length of a message relates to the amount of corruption the adversary must make 
during that message. 


• If i £ C then the first two bits of to,; were received correctly, and the possible noise can only be 
flipping some of the one-confirmation bits, i.e., the amount of corrupted bits is exactly con/ 0 . 
Since the message was eventually confirmed, it holds that confi — conf 0 = 1/e, and thus 
conf 0 = ( \rrii\ - 2 - l/e)/2. 

• For unconfirmed messages, i £ U, the message gets unconfirmed as soon as conf 0 > |n?.j|/3. 

There are two cases: (i) if the information/control bits are correct, then the noise is any 
O-confirmation bit, thus con/ 0 > |raj|/3; (ii) the information/control bits are corrupt, and 
then the noise is the corruption of the information/control plus any 1-confirmation bit. We 
have 3conf 0 > \nrii\ = (2 + con/ 0 + conf )) thus confi > — 1 > 

• For i € W, the corruption consists of at least one of the information/control bits and any 
confi received. We have confi ~ con fo > 1/e thus confi — con fo + 1/e or equivalently confi > 
(|m i |-2 + l/e)/2. 


Therefore, the global noise rate in any given simulation is lower bounded by 

X)iec(l m 'il - 2 — l/e)/2 + J2ieu \ m i\/3 + J2iew( l m *l + l/ e )/ 2 


Noise Rate > 


J2iec \ m i\ + Siec/ \ m i\ + Siew I m i 


We can rewrite the noise rate as 

\ Y^i&C \ m i\ _ l|C1(2 + 7) + l \ m 'i\ + \ Ysi&w \ m i\ + \ 


> 


n/e 2 


> 1 I Yjj^C \ m i\ ~ fl^K 2 + 7) + g J2i£W \ m ‘i\ + ■ \ 

3 


n/e 2 


> 1 + ISigc \ m i\ - ii\ c \ + | Eigm \ m i\ + ^1^ I _ Q, X 
— 3 n/e 2 


We now use the fact that the simulation instance we consider failed to simulate n correctly. Using 
Claim 4.4 we have that \C\ — 2\W\ < n, or equivalently, \W\ > \{\C\ — n). If \C\ < n it is trivial 
that the error rate is > 1/3 — 0(e). Otherwise, the error rate increases as we increase the length 
of messages in C and W. Since such messages are confirmed, they are of length > 1/e. Then, 


^ 1 | h\C\-m + M\C\-n) + U\C\~n) 

3 n/e 2 

>l-0( £ ). 


0(e) 


□ 
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5 Coding for Erasure Channels 


In this section we move to discuss erasure channels in which the noise may turn any symbol 
into an erasure mark _L. No feedback is assumed in this setting, so the sender is unaware of 
erased transmissions. As in the above sections we seek after the maximal erasure rates that robust 
protocols can deal with. In this setting the parties have no longer joint view, and reaching consensus 
(e.g., regarding who is the next to speak) is not a trivial task. In fact, similar to the case of standard 
noisy channels [BR11], any robust protocol must have a fixed (predetermined) order of speaking. 

Theorem 5.1. Any robust protocol over an erasure channel has a fixed order of speaking 

Proof. Let n be a protocol of length |7r| = N rounds. We denote erasure patterns as strings 
E E {0, _L} Ar : if ei = _L then the z-th transmission is erased, and if e* = 0 it is delivered intact. 
Denote with owner^^R, E) E {Alice, Bob} the party that owns round R < N (i.e., the sender) 
given the input (x, y ) and erasure pattern E E {0, -L}^. Note that for any E\. Eo that agree on the 
first R indices, owner Xjy (R, Ei) = owner Xj2/ (i?, E 2 ) i.e., the protocol is causal. 

Assume towards contradiction that the theorem does not hold. It easily follows that there 
must exist some input (x,y), a round R and two different erasure patterns Ea,Eb such that 
owner Xi?/ (i?, Ea) 7 ^ own er Xjy (R, Eb). Without loss of generality, assume Eb = _L A . Recall that 
erasures that occur after round R cannot affect the owner of round R, hence in the following we 
only consider patterns in { 0 , _L}^. 

Define a sequence of erasure patterns {Efi[f = 0 that starts with the pattern Ea , and adds at 
each step an erasure at the i-th from last round. More precisely, = Ea V for 0 < i < R. 

Here we treat 0 as a 0 and 1 as a 1, and V is the equivalent of a bitwise OR function. Note that 
Eq = Ea and Eb = Eb- Thus, there must exist some index 0 < i < R for which owner x , y (R, Ei) 
owner XiJ/ (i£, -E)+i). Fix this i for the rest of the proof. 

First, we claim that owner Xi y(ii — i, Ei) = owner x ,y(R — L Ei+ 1 ). This follows since the view of 
ovjr\er Xt y(R — i — 1, Ei) up to round R — i — 1 (including) is the same whether or not its transmission 
at the (R—i)- th round is erased by the channel. Then, the identity of party that owns the (R—i)- th 
round must be independent of whether the (R — z)-th transmission is erased, i.e., whether the noise 
is Ei or E l+X . 

Let p = owner Xi2/ (ii — i,Ef). Note that the view of p up to round R is the same for both E t 
and Ei + \, since up to round R — i — 1 the erasure pattern (and thus, the transcript) is exactly the 
same, round R — i is a message sent by p and after round R — i all the messages are erased, thus p 
cannot learn whether his message at the (R — i)-th round was erased or not. Hence, party p cannot 
distinguish the two cases, and it will error on the owner of round R , for either or E l+ \. □ 

It is already known that 1/2 is a tight bound on the erasure rate robust interactive protocols can 
tolerate over erasure channels [FGOS13]. Specifically, [FGOS13] shows that no protocol can resist 
an erasure level of 1/2, due to the trivial attack that completely erases one party. Furthermore, 
they show that for any e > 0, the coding scheme of [BR11] can tolerate an erasure level of 1/2 — e. 
However, that coding scheme has several drawbacks. First, it takes exponential time due assuming 
tree codes , a data structure whose efficient construction is still unknown (see [Sch96, GMS11, Bral2, 
MS14]). Furthermore, as e —> 0 and the erasure level approaches 1/2, the tree code needs to be 
more powerful, which implies the increase of the alphabet size (as a function of e). 

In the following subsection 5.1 we provide a simple, computationally efficient coding scheme for 
interactive communication over erasure channels in which the alphabet is small (namely, 6 -ary), 
and yet it tolerates erasure rates up to 1/2 — e. Then, in subsection 5.2 we transform this protocol 
to obtain the best known protocol for binary erasure channels, resisting an erasure level of up 
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to 1/3 — e. It is there where having a fixed, relatively small, alphabet leads to an improved noise 
tolerance. 

5.1 Erasure channels with a “large” alphabet 

Theorem 5.2. For any alternating noiseless binary protocol n of length n, and for any e > 0, 
there exists an efficient, deterministic, robust simulation of ir over an erasure channel with a 6-ary 
alphabet, that takes O e {n) rounds and succeeds assuming a maximal erasure rate of 1/2 — e. 

The main idea is the following. The parties talk in alternating rounds, in each of which they 
send a symbol m € Info x Parity where Info = {0,1} is the next information bit according to ir 
(given the accepted simulated transcript so far) and Parity = {0,1, 2} is the parity of the round in ir 
being simulated, modulus 3. 

Assume T is the transcript recorded so far, and let p = |T| mod 3. If a received m has 
parity p + 1, the receiving party accepts this message and extends T by one bit according to the 
Info part. Otherwise, or in the case m is erased, the party ignores the message, and resends its last 
sent message. 

Since messages might get erased, the parties might get out-of-sync , e.g. when one party extends 
its accepted T while the other party does not. However, this discrepancy is limited to a single bit, 
that is, the length of Alice’s T differs from Bob’s by at most ±1. Sending a parity—the length 
of the current T modulus 3—gives full information on the status of the other side, and allows the 
parties to regain synchronization. We formalize the above as Algorithm 3. 


Algorithm 3 Simulation for erasure channels 

Input: an alternating binary protocol i r of length n, s noise parameter e > 0, an input value x. 

Assume a fixed alternating order of speaking: Alice is the sender on odd i’s, and Bob is the sender on 
even i’s. 

1: Initialize: T 0, p 0, and m t— (0, 0). Set N = \n/e\. 

2: for i = 1 to N do 
3: if Sender then 

4: if your turn to speak according to 7r(- | T) then 

5: t send «- n(x | T) 

6: m «- {tsend, {p + 1) mod 3) 

7 : T <r~ T O tsend, 

8: pi— \T\ mod 3 

9: send m 

10: else 

11: send the m stored in memory 

12: if Receiver then 

13: record m' = ( t rec , p') 

14: if ml contains no erasures and p' = p + 1 mod 3 then 

15: T i — T O t r ec 

16: Output T 
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Proof. (Theorem 5.2.) First we set some notations for this proof. For a variable v denote with 
v a Alice’s instance of the variable (resp. vb for Bob’s instance) and with v(i) the state of the 
variable at the beginning of the i-th instance of the for-loop. For a string a = a[0] • • • a[k] denote 
by Trim(a) = a[0] • • • a[k — 1] the string obtained by trimming the last index, that is prefix fc _ 1 (a). 

Next, we analyze Algorithm 3 and show it satisfies the theorem. 

Claim 5.3. For any i < N, ||Ta(*)| — |Tg(i)|| < 1. 

Proof. We prove by induction on the round i. The base case i = 1 trivially holds. Now assume the 
claim holds up to the beginning of the i-th iteration of the loop. We show that the claim still holds 
at the end of the i-th iteration. 

We consider several cases, (a) |?A(i)| = |Tg(i)|. Then trivially each of Ta,Tb can extend by 
at most a single bit and the claim still holds. ( b) \Ta(i)\ = \Ts(i)\ + 1. Note that this situation is 
only possible if the |T/i(i)|-th round of n is Alice’s round: otherwise, in a previous round Ta was 
of length |Tg(i)| and it increased by one bit at line 15. But for this to happen, it must be that the 
received parity was p' = |Tg(i)| + 1. Yet, Tb never decreases, so such a parity could be sent by Bob 
only if at that same round, \Tb\ = \Ta\ + 1 — 3 k for some k G N. But then |Tg| < \Ta\ — 2, which 
contradicts the induction hypothesis. 

Consider round i. If i is odd, Alice just resends mn('i) from her memory, since according to T^(i) 
the next bit to simulate belongs to Bob; she thus doesn’t change Ta- Bob might increase Tg(i) 
since pa = Pb + 1- So the claim still holds for an odd i. If i is even, Bob is resending msif) since 
according to Tg(i) the next bit to simulate belongs to Alice. Yet Alice will not increase her Ta 
since the parity mismatches. There is no change in Ta,Tb in this case and thus the claim holds. 
The third case (c) |Tg(i)| = \Ta{i)\ + 1, is symmetric to ( b). □ 

Claim 5.4. For any i < N, Ta and Tb hold a correct prefix of the transcript of ir(x,y). 

Proof. Again, we prove by induction on the round i. The claim trivially holds for i = 1. Now, 
assume that at some round i, Ta(i) and Tb{i) are correct. We show they are still correct at 
round i + 1. 

Consider round i, and assume without loss of generality, that Alice is the sender. Then, if Alice 
adds a bit to Ta, this bit is generated according to n given a correct prefix Ta, which means that 
the generated bit is correct. As for the receiver, note that any message that contains erasures is 
being ignored. Thus, the only possibility for Tb to be incorrect is if the parties are out of sync, 
and Bob receives a message that does not correspond to the round of n that Bob is simulating. 
However, if Bob accepts the received bit it must be that the received parity satisfies p' = \Tb(i)\ +1 
mod 3. 

Since ||Ta(*)| — |Tg(i)|| < 1 (claim 5.3), there are two cases here. Either \Ta\ = \Tb\ which 
implies that Alice simulated the same round as Bob, and the received bit does correspond to the 
round simulated by Bob; or \Ta{i)\ / |Tg(i)|, so that Alice sent a message m that was stored in her 
memory, in which p 1 = |Tg(i)| + 1 mod 3. It is easy to verify that at any given round, the message 
saved in the memory is the one that was generated given the transcript Trim(T^) (otherwise, a new 
m . must have been generated by Alice). Along with the constraint on the parity, it must be the 
case that |Ta(*)| = |Tg(i)| + 1 which means the stored m is indeed the correct bit expected by Bob, 
and the claim holds in this case as well. □ 

After establishing the above properties of the protocol, we consider how the protocol advances 
at each round. We begin by exploring rounds in which the transmission is not erased. 
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Lemma 5.5. Assume that no erasure happens during the i-th transmission. Then, 

(a) if | T A (i)\ = \T b (i)\, then \T A (i + 1)| = \T A {i)\ + 1 = \T B (i + 1)|. 

(h) if i is even and \T A (i)\ < \T B (i)\, then \T A (i + 1)| = \T A (i)\ + 1. 

Proof. Part (a): trivial from Algorithm 3. Part (6): recall that this situation is only possible if 
\T B (i)\ = \T A {i)\ + 1 and that the |TB(z)|-th round in tt belongs to Bob (see the proof of claim 5.3 
above). Thus, if i is even, Bob is the sender, and since ir(y | T B {i )) is Alice’s round, Bob will 
retransmit the message m B (i ) stored in his memory; this corresponds to running tt given the 
transcript Trim(TB(z)) = T A (i). The parity in m B {i) is thus p B (i) = p A {i) + 1 and Alice accepts 
this transmission and extends T A . □ 

A symmetric claim holds for Bob, replacing even and odd rounds, and assuming \T B (i)\ < \T A (i)\. 
Next, consider rounds in which the transmission is erased. These can only cause the parties a 
discrepancy of a single bit in their (accepted) simulated transcripts. 

Lemma 5.6. Assume an erasure happens during the i-th transmission. 

If \T A (i)\ = \T B (i)\ then if i is odd, \T A (i + 1)| = \T A (i)\ + 1 while \T B {i + 1)| = \T B (i)\, and if i is 
even, \T B (i + l)\ = \T B (i)\ + l while |Th(i + l)| = \T A (i)\. Otherwise (i.e., |Ta(*)| / \T B {i)\), there 
is no change in T Al T B . 

Proof. For the first part of the lemma, assume j = |Ta(*)| = \T B (i)\. Let R be the first round for 
which \T a (R)\ = \T b (R)\ = j, and assume that at the previous round, \T A (R — 1)| < \T B {R — 1)|. 
Since the transcripts are of equal length at round R, Alice must have been the receiver at the R — 1 
round, which means that the (j — l)-th round of -k belongs to Bob. Therefore, the j-tli round of tt 
belongs to Alice, who is also the sender of round R in the simulation (i.e., R is odd), thus she 
extends her transcript in one bit at this round as well. Note that T never decreases, thus we must 
have that R = i, and the claim holds for this case. Also note that a similar reasoning applies for 
the edge case of i = 1. If instead we have \T A (R— 1)| > | T B (R — 1)|, a symmetric argument implies 
that Bob owns the j-th round of tt and is also the sender in the A-tli round (R = i is even), thus 
the claim holds for this case as well. 

Next, for the second part of the claim, assume that \T A (i)\ ^ \T B (i)\, and without loss of 
generality assume that \T A (i)\ < \T B (i)\. We know that the gap between the two transcripts is at 
most 1, thus if there is any change in these transcripts during the i-th rounds, either both parties 
increase their transcript, or only Alice does. Since the receiver sees an erasure, that party ignores 
the incoming message and doesn’t change his transcript, so it cannot be that both parties extend 
their transcripts. On the other hand, if \T B (i)\ = \T A (i)\ + 1 then the |Te(z)|-th round of tt belongs 
to Bob (see the proof of Claim 5.3), and Alice will increase T A only if she is the receiver. However, 
in this case Alice sees an erasure and ignores the message, keeping her transcript unchanged. □ 

Lemma 5.5 and Lemma 5.6 lead to the following corollary. 

Corollary 5.7. Any erasure causes at most two rounds in which neither T A nor T B extend. 

Proof. By Lemma 5.6, the only situation where there is no change in both T A ,T B at some round i 
where the transmission is erased, is when |T 4 (z)| ^ \T B (i)\. Then, in the next round i + 1 (in which 
the transcription is not erased), the transcripts will catch up if the sender is the party that holds 
the longer transcript. If this is not the case and the sender is the one with the shorter transcript, 
then in round i + 2 the sender is the one with the longer transcript, and the transcript must catch 
up by Lemma 5.5. In all other cases, at least one of the transcripts increases during round i or 
i + 1. □ 
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Thus, if the adversary is limited to making (1/2 — e)N = N/2 — n erasures, it must hold that 
\Ta(N) \ + \Tb(N)\ > N — 2 ■ (N/2 — n) =2 n and since ||Ta(iV)| — |7 b(IV)|| < 1, each of them must 
be of length at least n. This concludes the proof of the Theorem 5.2. □ 

5.2 Erasure channels with a binary alphabet 

By encoding each symbol from our 6 -ary alphabet using a binary code containing at least six 
codewords with maximal relative distance 5$ we can immediately get a binary scheme that resists 
erasure rates of up to 5q/2 — e. To our knowledge the maximal achievable distance 5q is 6/10 
(see [BBM + 78]). This leads to the following corollary: 

Corollary 5.8. For any alternating noiseless binary protocol n of length n, and for any e > 0, 
there exists an efficient, deterministic, robust simulation of ir over a binary erasure channel, that 
takes O e {n ) rounds and succeeds assuming a maximal noise rate of at most 3/10 — e. 

Finally, we use the above ideas to devise a binary protocol that resists an adversarial erasure 
rate of up to 1/3 — e. The idea is to reduce the number of different messages used by the underlying 
simulation: since Algorithm 3 assumes a 6 -ary alphabet, the best code has maximal distance 
5q = 6/10 which, as mentioned, leads to a maximal resilience of 5q/2 — e = 3/10 — e. However, were 
the alphabet in use smaller, say 4-ary, then we could have used better codes with a higher relative 
distance £4 = 2/3 and achieve a maximal resilience of <*> 4/2 — e = 1/3 — e. 

In the following we adapt Algorithm 3 to use an alphabet size of at most 4, and obtain the 
following. 

Theorem 5.9. For any alternating noiseless binary protocol 7 r of length n, and for any e > 0, there 
exists an efficient, deterministic, robust simulation of ir over a binary erasure channel, that takes 
O e (n) rounds and succeeds assuming a maximal noise rate of at most 1/3 — e. 

Proof. Each message in Algorithm 3 consists of two parts: an information bit, and a parity modulus 
three. In order to reduce the number of possible messages we introduce a simple preprocessing step 
that takes an alternating protocol ir of length n and converts it into a protocol n 1 of length 3n 
by padding each two consecutive transmutations of ir with two vacuous transmissions (say, of the 
value 1). That is, if the communication in 7 r is the bitstring a\, b\, 02 , 62 • • •, then in ir' the parties 
communicate a\, 1,1, b\, 1,1, 02, 1,1,... (recall that the protocol is alternating, thus Alice sends the 
odd bits, and Bob the even ones). 

In the preprocessed it' , both parties know that a bit of information lies only in transmissions 
whose parity is 0 (mod 3). Thus, for the other parities there is no need to send the information bit 
— it is always 1! This reduces the size of the alphabet in use, specifically, the parties send messages 
out of the following message space 4 

M = {0 x (mod 0 ) , 1 x (mod 0 ) , 1 x (mod 1 ) , 1 x (mod 2 )} . 

Now that the message space is of size 4 we can encode each message using a binary code of 
relative distance 64 = 2/3. For instance, we can use the code {000,011,110,101} (cf. [BBM + 78]). 
Similar to Algorithm 3, the obtained simulation is deterministic, efficient and takes O e {n ) rounds. 
As for its noise resilience, for any e > 0 the underlying Algorithm 3 can be set to resist up to 
1/2 — erased messages (Theorem 5.2). Since each message is coded into a binary string, in order 
to erase a codeword, 2/3 of its bits must be erased. Therefore, in the concatenated algorithm we 
can resist a maximal erasure rate of 2/3 • (1/2 — |e) = 1/3 — e. □ 

4 In Algorithm 3 the first information bit will actually have parity 1 rather than 0; we can alter M to have the 
information bit on parity 1 , and the rest remains the same. 
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